Users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server.
Users should upgrade to version 3.22.0.
There are no workarounds for versions < 3.22.0
1.0.01.1.11.10.01.11.01.12.11.13.01.14.11.15.21.16.01.17.0+166 more3.22.0Exploitability
AV:NAC:LAT:NPR:NUI:PVulnerable System
VC:NVI:NVA:NSubsequent System
SC:LSI:LSA:NCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N